MCP tools reference

The tools the V12 MCP server exposes, the scopes each needs, and which ones change data.

The V12 MCP server lists only the tools your token's scopes allow. Calling any other tool returns an insufficient_scope error. Each tool name is its REST operation's operationId in snake case: listFindings becomes list_findings. To connect a client, see Connect an MCP client.

Tools

ToolWhat it doesScopesREST equivalent
get_meGet the token identityGET /me
list_membersList organization membersuser:readGET /orgs/{org}/members
list_steersList Steersrepos:readGET /orgs/{org}/steers
get_steerGet a Steerrepos:readGET /orgs/{org}/steers/{steer}
list_repositoriesList repositoriesrepos:readGET /orgs/{org}/repositories
add_repositoryAdd a repositoryrepos:writePOST /orgs/{org}/repositories
list_refsList branches, pull requests and tagsrepos:readGET /orgs/{org}/repositories/{owner}/{repo}/refs
create_hosted_repositoryCreate a hosted repositoryrepos:writePOST /orgs/{org}/repositories/hosted
create_push_credentialGet a push URL for a hosted repositoryrepos:writePOST /orgs/{org}/repositories/{owner}/{repo}/push-credentials
list_repository_findingsList a repository's findings at a positionfindings:readGET /orgs/{org}/repositories/{owner}/{repo}/findings
list_findingsList organization findingsfindings:readGET /orgs/{org}/findings
update_findingsChange findingsfindings:writePATCH /orgs/{org}/findings
get_findingGet a findingfindings:readGET /orgs/{org}/findings/{finding}
comment_on_findingComment on a findingfindings:writePOST /orgs/{org}/findings/{finding}/comments
list_runsList runsruns:readGET /orgs/{org}/runs
start_runStart a runruns:writePOST /orgs/{org}/runs
get_runGet a runruns:readGET /orgs/{org}/runs/{run}
list_run_findingsList a run's findingsruns:read, findings:readGET /orgs/{org}/runs/{run}/findings
estimate_runEstimate a runruns:writePOST /orgs/{org}/runs/estimate
cancel_runCancel a runruns:managePOST /orgs/{org}/runs/{run}/cancel
list_run_linksList guest linksruns:shareGET /orgs/{org}/runs/{run}/links
create_run_linkCreate a guest linkruns:share, findings:readPOST /orgs/{org}/runs/{run}/links
update_run_linkChange a guest linkruns:share, findings:readPATCH /orgs/{org}/runs/{run}/links/{link}
revoke_run_linkRevoke a guest linkruns:shareDELETE /orgs/{org}/runs/{run}/links/{link}
request_document_uploadRequest a document upload slotruns:writePOST /orgs/{org}/documents/uploads
create_documentCreate a context documentruns:writePOST /orgs/{org}/documents
list_documentsList context documentsruns:readGET /orgs/{org}/documents
archive_documentArchive a context documentruns:writeDELETE /orgs/{org}/documents/{document}

create_run_link and update_run_link also need findings:write when the link's role is comment or triage. list_run_findings returns findings at each repository's analyzed commit. Each repository position uses kind: "commit" and a reusable at: "commit:<sha>", including for branch-only findings; webUrl opens finding detail in the repository workspace at that commit. Send position.at together with its repositories[i].repository to get_finding or update_findings. Without repository, V12 infers it and answers repository_required when more than one registered repository holds the finding at that position. status and codeState are evaluated at those commits: a later fix on the default branch leaves the run finding open. If the finding is present at current defaults, use get_finding without a position for its current state.

Tools that change data

Only these tools change data. Every other tool, estimate_run included, only reads, and says so with readOnlyHint: true.

  • add_repository, which adds a repository to the workspace; it spends no credits and starts no run
  • create_hosted_repository, which creates an empty repository V12 hosts
  • create_push_credential, which returns a Git URL that can push to one branch of a hosted repository for one hour; the URL is a secret
  • update_findings
  • comment_on_finding
  • request_document_upload
  • start_run, which spends credits
  • create_document
  • create_run_link, which returns the link's URL once, and update_run_link
  • cancel_run, revoke_run_link and archive_document, which also carry destructiveHint: true

Retrying start_run or comment_on_finding with the same requestId returns the original result instead of starting a second run or posting a second comment. Repeating add_repository needs no requestId: a repository already added comes back with added: false.

Results and errors

A successful call returns the same JSON as the REST response, as structured content and as text. A failed call sets isError and returns the REST error body; its codes are listed under Errors.

On this page